Skip to content

Change security policy to report directly to the Nix team #11468

Open
@roberth

Description

Describe the bug

The security policy https://github.com/NixOS/nix/security/policy requires reporting to the NixOS security team, but that indirection seems (EDIT: seemed to me) unnecessary and counterproductive, as it is important to work towards a patch ASAP.

I understand that @NixOS/security may want to be involved. Could we change the process so that the Nix team gets in touch with the security team instead? I believe their involvement is most relevant towards the end of the process.

Additional context

Priorities

Add 👍 to issues you find important.

Metadata

Assignees

No one assigned

    Labels

    bugidea approvedThe given proposal has been discussed and approved by the Nix team. An implementation is welcome.processIssues related to the development process of NixsecuritySecurity-related issues

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions